EI
AI Security Architecture Consultant (GenAI/ML Security)
Expert In Recruitment Solutions
🇺🇸 United States
Remote
Mid level
2 months ago
- AI/ML
- Machine Learning
- AI
- RAG
- Threat Modeling
- IAM
- RBAC
- ABAC
- DevSecOps
- Incident Response
- Secrets Management
- AWS
- Azure
- GCP
- OWASP
- Azure OpenAI
- OpenAI
- AWS Bedrock
- Vertex AI
- LangChain
- LlamaIndex
- CISSP
- CCSP
- Terraform
- CI/CD
2 months ago
We are seeking an experiencedAI Security Architect to support the secure design, development, and deployment of AI/ML and Generative AI solutions across the enterprise. This role will work closely with data science and engineering teams, product owners, cloud/platform teams, and the security architecture and operations groups to define and implement security requirements that enable compliant, resilient, and trustworthy AI adoption.
Key Responsibilities
- Collaborate with AI/ML engineering, data engineering, platform, and application teams to gather and analyze AI security requirements (data sourcing, model training, inference, integrations, and operational workflows).
- Define and documentsecure reference architectures for AI/ML and GenAI workloads across cloud and enterprise environments, including patterns for model hosting, RAG, agents, API exposure, and third-party model consumption.
- Performthreat modeling for AI systems (training and inference) including risks such as prompt injection, data leakage, model inversion/extraction, insecure plugins/tools, and supply chain risks.
- Establish security controls fordata protection across the AI lifecycle: dataset governance, data minimization, labeling/classification alignment, encryption, key management, secrets handling, and secure data access patterns.
- Define requirements and guardrails forGenAI safety and misuse prevention, including content filtering, prompt/response logging strategy, abuse detection, and safe tool execution.
- Partner with IAM teams to implementleast-privilege access for AI platforms, model endpoints, feature stores/vector databases, and supporting pipelines (service-to-service auth, token handling, RBAC/ABAC).
- Review and approve AI solution designs, ensuring alignment with security policies, regulatory expectations, and enterprise standards (secure SDLC/DevSecOps).
- Define requirements formodel governance and assurance (model provenance, versioning, artifact integrity, evaluation/validation controls, documentation, and auditability).
- Work with security operations to integrate AI platforms intomonitoring and incident response, including logging requirements, detection use cases, and response playbooks for AI-specific incidents.
- Contribute to security standards and best practices: "when to use enterprise controls vs platform-native controls,” secure configuration baselines, and reusable implementation guidance.
Required Qualifications
- 5+ years of experience in security architecture/engineering, with demonstrated experience securingcloud-native applications and APIs (AI/ML experience required).
- Strong understanding of AI/ML and GenAI solution patterns (model training vs inference, RAG, vector databases, agents/tool use, model endpoints).
- Proven ability to translate business and technical requirements intoactionable security controls and architecture decisions.
- Experience with cloud security fundamentals (network segmentation, IAM, encryption, secrets management, logging/monitoring) in at least one major cloud provider (AWS/Azure/GCP).
- Hands-on experience with application security and API security (authN/authZ, OWASP Top 10, secure SDLC, threat modeling).
- Familiarity with AI/ML security risks and mitigations (prompt injection, data leakage, jailbreaks, model theft, poisoning, insecure dependencies).
- Strong communication skills—able to document and present complex technical topics to engineering and leadership audiences.
- Ability to work independently and drive results in a fast-paced, multi-team environment.
- Experience securing enterprise GenAI platforms and services (e.g., Azure OpenAI/OpenAI APIs, AWS Bedrock, SageMaker, Vertex AI) and/or popular frameworks (e.g., LangChain/LlamaIndex) and vector databases.
- Experience with governance and compliance in regulated environments (financial services a plus).
- Familiarity with security evaluation/testing approaches for AI systems (red teaming, prompt testing, model risk assessments).
- Relevant certifications (examples): AWS/Azure/GCP security certifications, CISSP/CCSP, or equivalent experience.
- Experience with policy-as-code and automation (e.g., Terraform + scanning, CI/CD security controls).
AI Security Architecture Consultant (GenAI/ML Security) · Expert In Recruitment Solutions